Live data from Hacker News

Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

krebsonsecurity.com

21–30 of 102 posts

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#21
post #8

Maybe I'm a little ignorant on how/why companies store this sort of info. Someone at work informed me that Target storing CC numbers at least made sense when you needed to make a return. But at a Sonic Drive-In? I'm not returning my burger+shake combo. What is possessing Sonic to keep the number any longer than the period it takes to receive money from the CC company? And why is this period any longer than the 20 or…

Ignoring batch processing, they're also keeping this information in case of fraud issues, refunds, customer tracking for marketing purposes, etc. Even with PCI compliance you can store card information. You only can't store the CCV number. If your storing methods uses easy to circumvent encryption, then, ta-da, the hackers get all the credit cards.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#22
post #8

Maybe I'm a little ignorant on how/why companies store this sort of info. Someone at work informed me that Target storing CC numbers at least made sense when you needed to make a return. But at a Sonic Drive-In? I'm not returning my burger+shake combo. What is possessing Sonic to keep the number any longer than the period it takes to receive money from the CC company? And why is this period any longer than the 20 or…

> ... Target storing CC numbers at least made sense when you needed to make a return.

This is why I think the merchant processors should be instead be doing this by some kind of transaction ID. I.e. send the refund amount to the processor with the transaction ID instead of sending a new transaction to the card. It's more secure, and less error prone since you could build in checks for the amount returned and other such bits.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#23
post #8

Maybe I'm a little ignorant on how/why companies store this sort of info. Someone at work informed me that Target storing CC numbers at least made sense when you needed to make a return. But at a Sonic Drive-In? I'm not returning my burger+shake combo. What is possessing Sonic to keep the number any longer than the period it takes to receive money from the CC company? And why is this period any longer than the 20 or…

I don't believe in this case the hack targeted any cards held on file, as the article suggests it may have been a hack of the POS software system that would allow the thieves to copy the info from the magnetic strip as it was captured in real-time and then clone the card.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#24
post #13

Earlier quoted context omitted.

No they aren't. When did cash get 2 factor auth?

2FA is not inherently part of bitcoin's design. It's something that can be enabled, but not all implement it.

So I ask again... Where's Cash's 2 factor auth.

All of the major wallets/traders use 2FA and all the hardware wallets have it too.

It's like saying... Well there's safes and banks for cash but its something that not everyone "enables" but you and I both know they use it.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#25
post #8

Maybe I'm a little ignorant on how/why companies store this sort of info. Someone at work informed me that Target storing CC numbers at least made sense when you needed to make a return. But at a Sonic Drive-In? I'm not returning my burger+shake combo. What is possessing Sonic to keep the number any longer than the period it takes to receive money from the CC company? And why is this period any longer than the 20 or…

> ... Target storing CC numbers at least made sense when you needed to make a return. This is why I think the merchant processors should be instead be doing this by some kind of transaction ID. I.e. send the refund amount to the processor with the transaction ID instead of sending a new transaction to the card. It's more secure, and less error prone since you could build in checks for the amount returned and other su…

Every Payment processing system I have worked on did work that way, I did not need the card number to issue a refund only the AUTH Code

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#26
post #13

Earlier quoted context omitted.

Pretty much this. Bitcoins are like carrying around cash. Most folks will not argue that you own it, since it's in your pocket, but if someone picks your pocket in a crown then there's no way you're getting it back.

No they aren't. When did cash get 2 factor auth?

When has 2fa stop a bullet or knife?

Very little cash is stolen by pick-pockets or home burglars. People open their wallets because they fear pain, it doesn't matter how many locks are on the wallet.

relevant xkcd: https://xkcd.com/538/

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#27
post #14
post #5

Earlier quoted context omitted.

Wrong. In the US you may be liable for the full amount stolen if you fail to notice the theft in 30 days. Even if you report the theft promptly, the law allows your issuer to make you liable for the first $50. Also you completely ignored my point about hardware wallets making theft a non-problem.

Sure, so don’t ignore your finances for a month.

You will still be liable for $50. And you again ignored my point about hardware wallets making theft a non-problem.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#28

So I'm pretty ignorant to the history of personal identity/credit breaches, but for those who aren't, is this only getting to get worse? More and more companies are holding more and more data, to the point that these breaches seem to affect so many people. I entered the credit card game pretty recently, and almost immediately I'm affected by the Equifax breach. As a young person, this doesn't make the future of priva…

Someone should plot them to get an idea of how worse things are getting but it feels like we had one major data breach nearly every week for about 3 years now.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#29
post #2

Edit: it is sad that my comment that is relevant and contains nothing but facts is downvoted... What has HN become? Say what you want about Bitcoin, but it does solve credit card theft for good. If I could use my Bitcoin hardware wallet¹ to pay Sonic, I wouldn't be affected by this security breach. ¹ No Bitcoin theft has ever occurred on a hardware wallet thanks to their tamper proof isolation of private keys.

Yeah, if I keep my credit card in a safe and never use it, no fraud is going to happen. If I use it to pay for things multiple times a day, this happens. It's not like if there hasn't been bitcoins stolen in the past.
Post reply on HN